I. Scope
This Presidential Policy Directive (PPD) sets forth principles governing the Federal
Government’s response to any cyber incident, whether involving government or private
sector entities. For significant cyber incidents, this PPD also establishes lead Federal
agencies and an architecture for coordinating the broader Federal Government response.
This PPD also requires the Departments of Justice and Homeland Security to maintain
updated contact information for public use to assist entities affected by cyber incidents in
reporting those incidents to the proper authorities.
II. Definitions
1. Cyber incident. An event occurring on or conducted through a computer network
that actually or imminently jeopardizes the integrity, confidentiality, or availability
of computers, information or communications systems or networks, physical or
virtual infrastructure controlled by computers or information systems, or
information resident thereon. For purposes of this directive, a cyber incident may
include a vulnerability in an information system, system security procedures,
internal controls, or implementation that could be exploited by a threat source.
2. Significant cyber incident. A cyber incident that is (or group of related cyber
incidents that together are) likely to result in demonstrable harm to the national
security interests, foreign relations, or economy of the United States or to the public
confidence, civil liberties, or public health and safety of the American people.
III. Principles Guiding Incident Response
In carrying out incident response activities for any cyber incident, the Federal
Government will be guided by the following principles:
1. Shared Responsibility. Individuals, the private sector, and government agencies
have a shared vital interest and complementary roles and responsibilities in
protecting the Nation from malicious cyber activity and managing cyber incidents
and their consequences.
2. Risk-Based Response. The Federal Government will determine its response
actions and the resources it brings to bear based on an assessment of the risks posed
to an entity, our national security, foreign relations, the broader economy, public
confidence, civil liberties, or the public health and safety of the American people.
3. Respecting affected entities. To the extent permitted under law, Federal
Government responders will safeguard details of the incident, as well as privacy and
civil liberties, and sensitive private sector information, and generally will defer to
affected entities in notifying other affected private sector entities and the public. In
the event a significant Federal Government interest is served by issuing a public
statement concerning an incident, Federal responders will coordinate their
approach with the affected entities to the extent possible.
2/8